ln-24-architecture-decision-recorder
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to ingest and synthesize potentially untrusted data from the repository and external stakeholders into Architecture Decision Records (ADRs).
- Ingestion points: The skill reads repository instructions, Git state, existing decision conventions, and stakeholder statements (SKILL.md, Checklist items 1 and 2).
- Boundary markers: The instructions do not define delimiters or explicit "ignore embedded instructions" warnings for the external data being processed.
- Capability inventory: The skill is authorized to perform repository searches, direct document reads, and file system writes/patches to create ADR files in the
docs/architecture/decisions/directory (SKILL.md, Tool Routing). - Sanitization: There are no provisions for sanitizing, escaping, or filtering data extracted from external sources before it is interpolated into the generated documentation.
- [NO_CODE]: The skill consists exclusively of markdown instructions (SKILL.md) and does not include any accompanying scripts, binaries, or automated configuration files.
Audit Metadata